My understanding of GDPR and e-Privacy as it applies to a payment iframe like we're talking about here is that site A would get consent for B as a payment processing vendor, and then B would have a contract with A ("DPA") that ensures it doesn't do things outside of what A will be getting agreement for. In this case, I don't see how B running analytics JS is beyond what A already needs to be getting consent for.
(I used to work in this general area, but don't anymore.)